A Data Processing Agreement (DPA) is the contract that governs how we handle personal data on your behalf. Below is a summary of what's in ours — request a countersigned copy at the bottom of this page.
The parent (or school/organization) is the data controller for their child's profile and creations. Sketchlings acts as the data processor and processes personal data only on documented instructions.
Account email, child profile name and age band, drawings, generated images, and basic billing data — strictly to operate, secure, and improve the service.
Encryption in transit and at rest, least-privilege access, audit logging, and incident notification within 72 hours of confirmed personal-data breaches.
We publish a current list at /subprocessors and provide at least 30 days' notice before adding a new one that processes personal data.
Parents can export or permanently delete a child's account and all associated creations directly from the dashboard. We assist controllers with access, rectification, and erasure requests.
Where personal data is transferred outside its origin region, we rely on the European Commission's Standard Contractual Clauses (or local equivalents) with our subprocessors.
On termination or upon written request, personal data is deleted within 30 days, except where retention is required by law (e.g. tax records for paid plans).
This summary is provided for transparency and is not legal advice. The countersigned agreement is the binding document.
We'll respond within 5 business days with a draft DPA tailored to your jurisdiction. Submitting this form opens your email client.